---
title: "Use case 1: Event Triggered by DNS Query to a Threat Feed Domain"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDIntegrationCiscoISE/1544750557/Use%20case%201%3A%20Event%20Triggered%20by%20DNS%20Query%20to%20a%20Threat%20Feed%20Domain"
format: markdown
---
Endpoint making DNS query to a domain that triggers an Infoblox Threat Feed and meets defined policy apply criteria.

Source – 10.196.217.19

Policy apply criteria - (Severity = high and Confidence = high) and (policy_name = Default Global Policy)

![image-20250620-044610.png](media://6da49238-c4a3-4dcd-a560-e45bac24e642)

Running the command `dig magdalenawashington[.]net[.]` which has Severity High and Confidence level High, triggers the event as it meets the set criteria, and the endpoint is added to the quarantine list.

![image-20250620-045005.png](media://c28bcbca-5d93-43d5-b6f1-06bf1398882e)

![image-20250620-045032.png](media://9553e626-5dc9-4e36-ab20-5755669de5a0)

![image-20250620-045129.png](media://d4499579-eb06-4d3d-9222-1d80296d4515)

![image-20250620-045153.png](media://6cc741c2-f5b9-40a5-b9af-109127e903f1)

![image-20250620-045214.png](media://e904840d-3da3-4aa5-839f-0d119f648aab)